Let's Encrypt to test 64-day certificates on Wednesday
The standard validity of certificates will fall from 90 to 64 days in February 2027.
Let's Encrypt will begin testing TLS certificates valid for 64 days on Wednesday. The new standard will apply from 10 February 2027 to new and renewed certificates, meaning administrators will need to check their renewal automation.
Let's Encrypt currently issues certificates with a standard validity of 90 days. From 10 February 2027, that will become 64 days. This applies to certificates issued or renewed from that date; according to Let's Encrypt, existing valid certificates will not be revoked prematurely.
The test will begin on 14 October in the so-called staging environment. This environment is intended for testing changes without affecting production sites. Let's Encrypt advises administrators to check there whether their ACME client, scripts and deployment process handle the shorter validity period correctly.
For systems that support ACME Renewal Information, the transition should be largely automatic. ARI allows the certificate authority to tell the client when renewal would best take place. Administrators who have fixed dates or fixed intervals specified in scripts face a greater risk of a certificate being renewed too late.
The organisation therefore advises, among other things, searching for hard-coded values in cron jobs, scripts and internal manuals. Renewing at around two-thirds of the validity period should prevent a certificate from expiring. Warnings for failed renewals and automated reloading of certificates are also important.
The shorter validity period fits into a broader development in internet security. A certificate that was issued incorrectly or whose private key has been stolen remains valid for less time. At the same time, the risk shifts: security becomes more dependent on reliable automation and monitoring.
The change mainly affects organisations managing many websites, APIs or servers. For most users, nothing will change in the daily use of secure websites. A further step towards standard certificates valid for 45 days is also planned for 2028. Wednesday's test is therefore not only a check of the forthcoming change, but also preparation for shorter renewal cycles.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The technical timetable and recommended preparations correspond to Let's Encrypt's official announcement. The text distinguishes between confirmed changes and the security goals cited by the organisation.
- confirmed Let's Encrypt will test certificates valid for 64 days from 14 October 2026. — Official announcement by Let's Encrypt. source
- confirmed The standard change will take effect on 10 February 2027. — Official timetable from Let's Encrypt. source
- confirmed Existing valid certificates will not be revoked because of the transition. — Explicitly stated by Let's Encrypt. source
- confirmed ARI can help clients determine the renewal time automatically. — Description in the official announcement. source
- confirmed A further step towards 45-day validity is planned for 2028. — Mentioned in Let's Encrypt's timeline. source
Editor's note
The test date, production date and technical consequences were checked directly with Let's Encrypt and compared with Ars Technica and Tweakers. The security benefit is described as a goal and rationale, not as an independently measured effect.Sources
More on this in Dutch media
- De Telegraaf — „let's encrypt”
- de Volkskrant — „let's encrypt”
- NOS — „let's encrypt”